Skip to content

sqlite3: Blob crashes when using a negative-step slice #150449

Description

@ever0de

What happened?

sqlite3.Blob crashes when you use a negative step in a slice — both for reading and writing.
The sequence operations docs say s[i:j:k] with negative k is valid, and bytearray handles it fine.

import sqlite3

con = sqlite3.connect(":memory:")
con.execute("CREATE TABLE t(b BLOB)")
data = b"this blob data string is exactly fifty bytes long!"
con.execute("INSERT INTO t(b) VALUES (?)", (data,))

# bytearray works
ba = bytearray(data)
ba[9:0:-2] = b"12345"
print(ba)
# b't5i4 3l2b1data string is exactly fifty bytes long!'

# Blob crashes
blob = con.blobopen("t", "b", 1)
blob[9:0:-2] = b"12345"
blob.close()
>>> blob[9:0:-2] = b"12345"
Traceback (most recent call last):
  File "<stdin>", line 1, in <module>
SystemError: Negative size passed to PyBytes_FromStringAndSize

Reading also crashes: blob[9:0:-2] raises the same error.

On Python 3.11.6 and 3.14.5 the error is SystemError: Negative size passed to PyBytes_FromStringAndSize.
On the current main branch read_multiple was changed to use PyBytesWriter_Create, so the message is now ValueError: size must be >= 0 — but the root cause is the same.

CPython versions tested on:

3.11.6, 3.14.5, main(629da5c)

Operating systems tested on:

macOS - 26.3.1 (a)(25D771280a)


Related


I'd like to work on a fix for this. I'll submit a PR.

Linked PRs

Activity

  1. added a commit that references this issue on May 26, 2026
  2. added 3 commits that reference this issue on May 26, 2026
  3. serhiy-storchaka commented on May 29, 2026

    @serhiy-storchaka
    Member

    Not all sequences support extended slices (with step), especially with step < 0. Does it currently work with positive step? Supporting step < 0 is a new feature, this change can only go in main.

    But crash and SystemError are unacceptable. In older versions we need to raise a TypeError or a ValueError for step < 0.

  4. ever0de commented on May 30, 2026

    @ever0de
    ContributorAuthor

    Not all sequences support extended slices (with step), especially with step < 0. Does it currently work with positive step? Supporting step < 0 is a new feature, this change can only go in main.

    Yes, positive steps already work.

    Test results on Python 3.13.4:

    blob[0:10:2] = [0, 2, 4, 6, 8]
    blob[0:15:3] = [0, 3, 6, 9, 12]
    blob[1:10:2] = [1, 3, 5, 7, 9]
    after write blob[0:10:2] = [65, 66, 67, 68, 69]
    blob[9:0:-2] raises SystemError: Negative size passed to PyBytes_FromStringAndSize
    

    The Python data model notes that step support is optional:

    Some sequences also support “extended slicing” with a third “step” parameter
    Data Model §3.2.5 Sequences

    Since positive steps already work, I was wondering: once a type accepts a step argument at all, should it handle both positive and negative steps? Or is step < 0 still considered a separate addition?

    Either way, I'll prepare backport PRs that raise ValueError for step < 0 in 3.13, 3.14 and 3.15.

    https://devguide.python.org/versions/

  5. added 5 commits that reference this issue on May 30, 2026
  6. 9 remaining items

  7. added 2 commits that reference this issue on Jun 5, 2026
  8. added a commit that references this issue on Jun 8, 2026
  9. added 4 commits that reference this issue on Aug 11, 2026
  10. added
    3.13only security fixes
    3.14bugs and security fixes
    3.15bugs and security fixes
    3.16new features, bugs and security fixes
    type-featureA feature request or enhancement
    on Aug 14, 2026
  11. serhiy-storchaka commented on Aug 14, 2026

    @serhiy-storchaka
    Member

    So, 3.16 got a correct support for negative indices, 3.13-3.15 will get a bugfix.

  12. added a commit that references this issue on Aug 14, 2026
  13. added a commit that references this issue on Oct 9, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    3.13only security fixes3.14bugs and security fixes3.15bugs and security fixes3.16new features, bugs and security fixesextension-modulesC modules in the Modules dirtopic-sqlite3type-bugAn unexpected behavior, bug, or errortype-featureA feature request or enhancement

    Projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions